Tailnet orion · tin-otter.ts.net

Access as Geography

Devices grouped by where they physically sit. Lines are grants — directed: the source initiates, the target never answers back.

This is a demo. Every device, user, site and network below is invented — but it is rendered by the real code, not mocked up. Source and setup: github.com/crazyhoesl/tailnet-atlas

23devices
20online
4grants
4sites
4owners
hover a node · click to pin · click a role to filter
atlas.live · 04 Aug 2026 · 15:19:47
01

Devices

23 nodes. Placement follows the address a device was last given by the network it joined — for the travel routers that is their uplink, not the LAN they serve.

DeviceTailscale IPLocal · siteOSRoles
atlas100.82.62.24172.25.0.3 ·docklinux
server
backups100.81.53.21172.22.0.2 ·docklinux
server
cloud-exit100.82.77.2910.0.19.7 ·mobilelinux
exitupdate available
crate100.80.14.8192.168.10.30 ·lisbonlinux
server
doorbell-relay100.82.59.23172.24.0.3 ·docklinux
ha-access
hub100.80.11.7192.168.10.20 ·lisbonlinux
exithomeserversubnet192.168.10.0/24
kitchen-tablet offline100.80.26.12192.168.10.52 ·lisbonandroid
clientha-access
living-room-tv100.80.23.11192.168.10.51 ·lisbonandroid
clientupdate available
metrics100.81.50.20172.21.0.2 ·docklinux
serverupdate available
mila-ipad offline100.82.74.28172.20.10.4 ·mobileios
clientha-accessuser: mila
mila-laptop100.81.41.1710.20.30.44 ·berlinwindows
client-fulluser: mila
nadia-pixel100.80.20.10192.168.10.42 ·lisbonandroid
client-full
notes100.81.47.19172.19.0.3 ·docklinux
server
office-nuc100.81.35.1510.20.30.2 ·berlinlinux
exitserversubnet10.20.30.0/24user: mila
photos100.81.44.18172.19.0.2 ·docklinux
server
plotter100.81.38.1610.20.30.31 ·berlinlinux
clientuser: mila
recipes100.81.56.22172.23.0.2 ·docklinux
ha-accessserver
theo-iphone100.80.29.13192.168.10.53 ·lisbonios
clientha-accessuser: theo
theo-macbook100.80.32.14192.168.10.54 ·lisbonmacos
client-fulluser: theo
thinkpad-x1100.80.17.9192.168.10.41 ·lisbonlinux
client-full
trip-router offline100.82.71.27172.20.10.6 ·mobilelinux
exitserversubnet192.168.9.0/24
van-router100.82.68.2610.44.2.87 ·mobilelinux
exitserversubnet192.168.8.0/24
wiki100.82.65.25172.26.0.2 ·docklinux
server
02

Grants

Directed rules from the live policy file. Anything not listed here is denied.

#SourceTargetPortsEdges drawn
1client-fullserver · homeany48
2clienthome443 81235
3ha-accesshome81235
4serverhome51411
03

Sites

Physical grouping. Containers share their host's uplink, so they form their own cluster.

SiteNetworkDevicesRoles present
Lisbon · home192.168.10.0/248
clientfullhomeserver
Berlin · office10.20.30.0/243
clientfullserver
Mobile · roamingphones · travel routers4
clientexitserver
Docker @ crate172.16/12 bridges8
proxyserver
04

Owners

Who a device belongs to. Access itself is granted by tag, never by person — ownership decides who can remove or re-authorise a node. On the map a device owned by someone else carries a solid outer ring, one owned by its tag a dashed one; unmarked nodes belong to the tailnet owner.

OwnerRoleOnlineSitesDevices
nadia
nadia@github
owner12/14Docker @ crate
Lisbon · home
Mobile · roaming
backups cloud-exit crate hub kitchen-tablet living-room-tv metrics nadia-pixel notes photos thinkpad-x1 trip-router van-router wiki
mila
mila@github
member3/4Berlin · office
Mobile · roaming
mila-ipad mila-laptop office-nuc plotter
theo
theo@github
member2/2Lisbon · home
theo-iphone theo-macbook
tag-ownedtag-owned3/3Docker @ crate
atlas doorbell-relay recipes
05

How placement works

Nothing here is hand-assigned — every device is re-located on each refresh.

StepRuleWhy
1. CollectTake every private address the device was last seen on (10.x, 172.16-31.x, 192.168.x).Tailscale reports all interfaces, not just the useful one.
2. Drop self-hostedIgnore any address ending in .1 — the gateway of a network the device hands out itself.Travel routers carry their own LAN everywhere; it says nothing about location. Same for Docker bridges.
3. Match a place192.168.10.x → Lisbon · home
10.20.30.x → Berlin · office
172.20.10.x → Mobile · roaming
Only networks bound to a physical location count. The hotspot range is listed so it is not mistaken for a Docker bridge — both sit inside 172.16/12.
4. DockerAnything left inside 172.16/12 joins the Docker @ crate cluster.Containers share the host's netns and have no LAN of their own.
5. OtherwiseMobile · roaming.Mobile data, a hotspot or an unknown network — the device is not at any known site.
6. Pinnedcloud-exit always counts as roaming.A datacenter VM has no LAN that would place it anywhere meaningful.

Rules are rendered from the same constants the placement code uses, so this table cannot fall out of sync. A device that is offline keeps its last known address, and therefore its last known site, until it checks in again.

Built live from the Tailscale API · background refresh every 5 min While this page is open it polls every 10s, for up to 5 min of viewing time Read-only · status at /healthz